Academy/VMware Avi Load Balancer 30.x Specialist (6V0-22.25)/TLS 1.2 vs. TLS 1.3 Handshake Comparison
This lab targets VCF 9.0

TLS 1.2 vs. TLS 1.3 Handshake Comparison

VCF 9.0Intermediatespecialist⏱ 75 min

Objectives

  • Configure two Virtual Services (one TLS 1.2, one TLS 1.3); measure handshake time; compare latency.

Prerequisites

VCF lab environment deployed and operational

Lab Environment

Standard VCF lab environment for Avi Load Balancer 30.x Specialist

Tasks

Task 1 TLS 1.2 vs. TLS 1.3 Handshake Comparison

Configure two Virtual Services (one TLS 1.2, one TLS 1.3); measure handshake time; compare latency.

Step 1

Create VS with TLS 1.2 Only:

Step 2

Create VS with TLS 1.3 Only:

Step 3

Capture TLS Handshake (Wireshark on Client):

Step 4

Measure HTTP Request Latency:

Step 5

Validation Checklist: TLS 1.2 handshake ~150 ms (3 RTT)TLS 1.3 handshake ~50 ms (1 RTT)TLS 1.3 resumption ~2 ms (session ticket reuse)HTTP request latency reduced with TLS 1.3Ciphers correctly negotiated (via Wireshark)

Validation Gate

Check: Verify lab completion

Expected: Lab exercise completed successfully

Common Errors

TLS 1.3 cipher suite not compatible with legacy clients
Fix: TLS 1.3 uses a different cipher suite format (TLS_AES_128_GCM_SHA256) than TLS 1.2 (ECDHE-RSA-AES128-GCM-SHA256). Legacy clients (older browsers, Java 8) may not support TLS 1.3. Configure Avi SSL profile to accept both TLS 1.2 and 1.3 for backward compatibility while preferring 1.3.
Certificate chain incomplete in Avi SSL profile
Fix: Avi requires the full certificate chain: server cert + intermediate CA(s). Missing intermediate CA causes browser 'untrusted certificate' errors even though the server cert is valid. Upload the complete chain in the SSL/TLS certificate configuration.
OCSP stapling not enabled causing client-side certificate validation delays
Fix: Without OCSP stapling, clients must contact the CA's OCSP responder to verify certificate validity — adding 100-500ms latency. Enable OCSP stapling in Avi SSL profile: Avi pre-fetches OCSP responses and includes them in the TLS handshake.

Final Validation

Lab completed successfully

✓ All steps completed → No errors observed

Cleanup / Restore

• Revert to snapshot if needed

Design Reflection (VCDX)

TLS architecture shows security design awareness. VCDX panelists test certificate chain management, protocol version selection, and performance impact of encryption.

⚠ Known Pitfalls (from Community KB)

Enabling TLS 1.3 only without backward compatibility — breaks legacy client access.
Incomplete certificate chain — causes intermittent trust failures depending on client CA cache.
Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.